agent build
This commit is contained in:
@@ -104,9 +104,17 @@ services:
|
||||
# with credentials, so it would break authenticated calls rather than
|
||||
# loosen anything.
|
||||
HTTP_CORS_ORIGINS: ${HTTP_CORS_ORIGINS:-}
|
||||
# lax | none | strict. "none" is required when the frontend is on a
|
||||
# different registrable domain from the API — otherwise the browser
|
||||
# withholds the cookie however correct the CORS headers are.
|
||||
# lax | none | strict, or unset to let the server choose.
|
||||
#
|
||||
# "none" is required when the frontend is on a different registrable
|
||||
# DOMAIN from the API — otherwise the browser withholds the cookie
|
||||
# however correct the CORS headers are. A different ORIGIN on the same
|
||||
# domain (platform.krowforce.com → mcp.krowforce.com) needs CORS but not
|
||||
# this: a Lax cookie already travels between them, and "none" would give
|
||||
# up the only CSRF protection this API has.
|
||||
#
|
||||
# Unset, the server derives it from HTTP_CORS_ORIGINS. The default below
|
||||
# is deliberate: a compose deployment keeps Lax unless told otherwise.
|
||||
HTTP_COOKIE_SAMESITE: ${HTTP_COOKIE_SAMESITE:-lax}
|
||||
DATABASE_MAX_OPEN_CONNS: ${DATABASE_MAX_OPEN_CONNS:-25}
|
||||
DATABASE_MIN_IDLE_CONNS: ${DATABASE_MIN_IDLE_CONNS:-2}
|
||||
|
||||
Reference in New Issue
Block a user